Edward Snowden’s name entered the cultural lexicon in 2013, after he leaked thousands of classified National Security Agency documents to journalists. He’s been variously called a traitor, a patriot, a revolutionary, a dissident and a whistleblower, but however you personally feel about him, there’s one way to categorize him that no one can dispute: He’s a thief.

There’s no doubt about it: Snowden’s information didn’t belong to him, and the scary truth is that he is neither the first nor the last employee to attempt to smuggle secrets out of a building – and we need to learn from his success to try to prevent it from happening again.

Since the dawn of the digital age, we’ve fought cyber pirates with tools like firewalls, encryption, strong passwords, antivirus software and white-hat hackers. But with so much attention on protecting against cyber risks, we sometimes forget about the other side of the coin: the risk that data will be physically removed from the building.

Douglas Miorandi, director of federal programs, counter-terrorism and physical data security for Metrasens, recently discussed the major risks to physical data security with SecurityInformed.com.


Q: What Do You Believe Are The Main Physical Threats To Data?

The biggest threats I have seen in the physical data security space have varied over the years, but there are four specific risks that remain the same across the board for any organization, which are:

Every organization is at risk of having data walk out the building with that employee

  • The Insider Threat
  • The Outsider Threat
  • The Seemingly Innocent Personal Item
  • Poor or Nonexistent Screening

To beginning with, every company or government agency has at least one disgruntled employee working for them, whether they know it or not, and that means every organization is at risk of having data walk out the building with that employee. That is what security experts call the insider threat.


Q: What Do You Think Influences Employees To Steal Data From Their Own Organization?

People steal data from their workplaces because they see some means to an end, whether it’s to expose something embarrassing or damaging due to a personal vendetta, or because they can sell it to a competitor or the media and benefit financially – meaning they don’t even need to be disgruntled; they might just want a quick way to make a buck. Financial data, too, is attractive, both for insider trading and selling to the competition.

Financial data, too, is attractive, both for insider trading and selling to the competition
People steal data from their workplaces because they see some means to an end, whether it’s to expose something embarrassing or damaging due to a personal vendetta, or because they can sell it to a competitor or the media and benefit financially

This can happen to both private companies as well as government agencies. Take Natalie Mayflower Sours Edwards for example, a Treasury Department employee who was caught in the act just last month, when she disclosed sensitive government information about figures connected to the Russia investigation to a reporter. She didn’t hack the system, she simply used a flash drive. And let’s not forget that Snowden was a contractor working for the NSA.


Q: Many Of Us Think Of Security Threats Coming From An Outsider, Do Companies Still Face These Type Of Threats?

Yes. Unfortunately, organizations do not only need to worry about their own employees – companies and government agencies need to be wary of threats from outsiders.

COTS devices include SD cards, external hard drives, audio recorders and even smart phones

They can come in the form of the corporate spy – someone specifically hired to pose as a legitimate employee or private contractor in order to extract information – or the opportunistic thief – a contractor hired to work on a server or in sensitive areas who sees an opening and seizes it. Either one is equally damaging to sensitive data because of the physical access they have.


Q: Whether It Be An Insider Threat Or An Outsider Threat, What Are Ways These Individuals Can Steal Sensitive Data?

 There are two types of personal items that can be used to steal data: the commercially available off-the-shelf (COTS) variety, and the intentionally disguised variety. This is considered risk number three – the seemingly innocent personal item.

COTS devices include SD cards, external hard drives, audio recorders and even smart phones, any of which can be used to transport audio, video and computer data in and out of a building.

Intentionally disguised devices are straight out of the spy novel; they could be a recording device that looks like a car key fob, or a coffee mug with a USB drive hidden in a false bottom.


Organisations do not only need to worry about their own employees – companies and government agencies need to be wary of threats from outsiders
Intentionally disguised devices are straight out of the spy novel; they could be a recording device that looks like a car key fob, or a coffee mug with a USB drive hidden in a false bottom

Q: What Is The Difference Between COTS And Disguised Devices?

The difference between COTS and disguised devices is that if someone gets caught with a COTS device, security will know what it is and can confiscate it. The disguised device looks like a security-approved item anyone could be carrying into the workplace, making it especially devious.

Sometimes these devices don’t just function to bring information out of a building; they are used to damage a server or hard drive once it’s plugged in to a computer or the network. Some are both – a recording device that extracts data and then destroys the hard drive.



Companies with airtight cyber security protocols can sometimes fall down when it comes to physically screening peopleQ: With These Types Of Discrete Items, Can Security Personnel Still Catch Individuals In The Act? For Example, Through Security Screenings?

Poor or nonexistent screening is the most substantial security threat to any organization when it comes to sensitive data. Whether it’s an employee, an outside contractor or a device, the physical security risks are real, and everyone and everything entering and leaving a building needs to be screened.

Unfortunately, screening often isn’t occurring at all, or is ineffective or inconsistent when it does occur. Even companies with airtight cyber security protocols can sometimes fall down when it comes to physically screening people and stopping them from stealing data through recording devices.



Q: It’s Surprising That So Many Organizations Would Neglect Physical Security When Protecting Their Data.

It’s a huge mistake, and the consequences can be dire. They range from loss of customer trust, exorbitant lawsuits and tanking stock prices in the private sector; and risks to national security in the public sector. Costs and resource allocation increase as well during efforts to reactively fix or mitigate the effects of physically stolen data.

For both the private and public sectors, the risk for data to be physically removed from a building has never been greater. Years ago, it was much harder for the average Joe to figure out where they could sell stolen data. Now, with the Deep Web, anyone with Tor can access forums requesting specific information from competing spy agencies, with instructions on how to deliver it, greatly reducing the risk of getting caught – and increasing the likelihood people will try it.

Although it’s getting easier to sell data, the good news is that all of these threats are avoidable with the right measures.


With the Deep Web, anyone with Tor can access forums requesting specific information from competing spy agencies
Physical data security and cybersecurity must be considered the yin and yang of an airtight policy that effectively protects sensitive or confidential assets from a malicious attack


Q: So How Can An Organization Protect Against These Risks?

There are a number of ways – and the first one requires a change of mindset. Not long ago, the building/physical security department and the IT/cybersecurity department were considered two different entities within an organization, with little overlap or communication.

organizations now are realizing that, because of the level of risk they face from both internal and external threats, they must take a holistic approach to data security. Physical data security and cybersecurity must be considered the yin and yang of an airtight policy that effectively protects sensitive or confidential assets from a malicious attack.



Q: How Can Companies And Government Agencies Combine Both Physical Data Security And Cybersecurity Initiatives?

Physical security managers can advise cybersecurity managers on ways to reinforce their protocols – perhaps by implementing the newest surveillance cameras in sensitive areas, or removing ports on servers so that external drives cannot be used.

Organizations need to create an effective program and ensure it stays effective so people know it’s not worth the hassle to try

In turn, the cybersecurity team can let the physical security team know that they have outside contractors coming in to work on the server, and the physical security team can escort the contractors in and stand guard as they work.

Constant communication and a symbiotic relationship between the two departments are crucial to creating an effective holistic security protocol and, once you’ve got the momentum going, don’t let it slow down. Sometimes efforts start off strong and then peter out if priorities change. When guards are down, it’s an excellent time for a malicious actor to strike. organizations need to create an effective program and ensure it stays effective so people know it’s not worth the hassle to try.

It’s not just about the mentality, though. Using the right technology is just as important.



Q: What Type Of Technology Can You Use To Protect Physical Data?

Many problems can be avoided by simply using the right technology to detect devices that bring threats in and carry proprietary information out.

Electronics such as hard drives, cell phones, smart watches, SD cards and recording devices have a magnetic signature because of the ferrous metals inside them. Using a ferromagnetic detection system (FMDS) as people enter and exit a building or restricted area means that anything down to a small microSD card triggers an alert, allowing confiscation or further action as needed.


FMDS can see through body tissue and liquids, so items cannot be concealed anywhere on a person or with their belongings
Electronics such as hard drives, cell phones, smart watches, SD cards and recording devices have a magnetic signature because of the ferrous metals inside them


Q: How Does FMDS Work?

In the most basic terms, FMDS uses passive sensors that evaluate disturbances in the earth’s magnetic field made by something magnetic moving through its detection zone. Nothing can be used to shield the threat, because FMDS doesn’t detect metallic mass; it detects the magnetic signature, down to a millionth of the earth’s magnetic field. FMDS is the most reliable method of finding small electronics items and should be part of the “trust, but verify” model

Although it is a passive technology, it is more effective and reliable than using hand wands or the walk-through metal detectors typically seen in an airport, which cannot detect very small ferrous metal objects. FMDS can see through body tissue and liquids, so items cannot be concealed anywhere on a person or with their belongings.

Whether or not the items are turned on doesn’t matter; FMDS doesn’t work by detecting a signal, but rather by spotting the magnetic signature that electronics contain. This is ideal, because most recording devices do not emit any signal whatsoever.

In my experience, FMDS is the most reliable method of finding small electronics items (as well as other ferrous metal objects, like weapons), and should be part of the “trust, but verify” model, in which companies assume the best of their employees and anyone else entering the building, but still take necessary precautions.



Q: What Are The Key Takeaways For Organizations Looking To Enhance Data Security?

The toughest challenge in the security sector – whether it’s cyber or physical – is remembering that the bad guys are constantly looking for ways to slip in through the cracks, and security departments need to stay one step ahead to ward off both internal and external threats. Recognizing the existing threats, putting together a holistic security strategy, and using the right technology to detect illicit devices comprises an effective three-pronged approach to protecting an organization’s data.

Organizations cannot afford to be passive about security and assume employees won’t steal data and spies won’t sneak in. Strong countermeasures are necessary because data loss can come from both inside and outside, in both private and public sectors, from places not everyone thinks of – and with technology like FMDS acting as a backup to the human element, organizations can lock down their data and keep the wolves in sheep’s clothing from getting through the door.

Share with LinkedIn Share with Twitter Share with Facebook Share with Facebook
Download PDF version Download PDF version

Author profile

Douglas Miorandi Director, Federal Programs and High-Security, Metrasens Ltd

In case you missed it

The Post-Pandemic Mandate For Entertainment Venues: Digitally Transform Security Guards
The Post-Pandemic Mandate For Entertainment Venues: Digitally Transform Security Guards

As the COVID-19 pandemic wanes and sporting venues open-up to full capacity, a new disturbing trend has hit the headlines - poor fan behavior. Five NBA teams have issued indefinite bans on fans, who crossed the line of unacceptable behavior, during the NBA playoffs. Major League Baseball stadiums have a recurring problem with divisive political banners being strewn over walls, as part of an organized campaign, requiring fan ejections. There was a brawl between Clippers and Suns fans after Game 1 of their playoff series. And, the U.S. vs. Mexico Nations League soccer game over the Fourth of July weekend had to be halted, due to fans throwing objects at players and screaming offensive chants. Cracking down on poor fan behavior Security directors are consistently reporting a disturbing uptick in poor fan attitude and behavior With players across all major sports leagues commanding more power than ever before, they are demanding that sports venues crack down on poor fan behavior, particularly when they are the targets of that behavior. Whether it’s an extension of the social-media divisiveness that’s gripped society, or people unleashing pent up negative energy, following 15 months of social isolation, during the COVID-19 global pandemic, security directors are consistently reporting a disturbing uptick in poor fan attitude and behavior. They’re also reporting a chronic security guard shortage, like many businesses that rely on relatively low-cost labor, finding candidates to fill open positions has been incredibly difficult. Low police morale To add the third component to this perfect storm, many police departments are struggling with morale issues and officers are less likely to put themselves into positions, where they could wind up in a viral video. According to the Police Executive Research Forum, police officer retirements in the U.S. were up 45% in the April 2020 - April 2021 period, when compared to the previous year. Resignations were up 18%. In this environment, officers may be less likely to undertake fan intervention unless it’s absolutely necessary. This can seem like the worst of times for venue security directors, as they need more staff to handle increasingly unruly patrons, but that staff simply isn’t available. And, because the security guard staffing industry is a commoditized business, companies compete almost solely on price, which requires that they keep salaries as low as possible, which perpetuates the lack of interest in people participating in the profession. Digital Transformation There is only one way out of this conundrum and that is to make security personnel more efficient and effective. Other industries have solved similar staffing and cost challenges through digital transformation. For example, only a small percentage of the total population of restaurants in the U.S. used to offer home delivery, due to cost and staffing challenges of hiring dedicated delivery personnel. Advent of digital efficiency tools But with the advent of digital efficiency tools, now virtually all restaurants can offer delivery But with the advent of digital efficiency tools, such as UberEATS and DoorDash, now virtually all restaurants can offer delivery. Likewise, field-service personnel are digitally connected, so when new jobs arise, they can be notified and routed to the location. Compare this to the old paper-based days, when they wouldn’t know about any new jobs until they picked up their work schedule at the office, the next day and you can see how digital transformation makes each worker significantly more efficient. Security guards and manned guarding The security guard business has never undergone this kind of digital transformation. The state-of-the-art ‘technology’ has never changed - human eyes and ears. Yes, there are video cameras all over stadiums and other venues, but behind the scenes is a guard staring at a bunch of monitors, hoping to identify incidents that need attention. Meanwhile, there are other guards stationed around the stadium, spending most of their time watching people who are doing nothing wrong. Think about all the wasted time involved with these activities – not to mention the relentless boredom and ‘alert fatigue’ from false-positive incident reporting and you understand the fundamental inefficiencies of this labor-based approach to security. Now think about a world where there’s ubiquitous video surveillance and guards are automatically and pre-emptively notified and briefed, when situations arise. The fundamental nature of the security guards profession changes. Instead of being low paid ‘watchers’, they instead become digitally-empowered preventers. AI-based screening and monitoring technology This world is happening today, through Artificial Intelligence-based screening and monitoring technology. AI-powered weapons-detection gateways inform guards, when a patron entering the venue is carrying a gun, knife or other forbidden item. Instead of patting down every patron with metal in their pockets, which has been the standard practise since walk-through metal detectors were mandated by sports leagues following 9/11, guards can now target only those who are carrying these specific items. Video surveillance and AI-based analytics integration Combining surveillance video with AI-based advanced analytics can automatically identify fan disturbances Combining surveillance video with AI-based advanced analytics can automatically identify fan disturbances or other operational issues, and notify guards in real time, eliminating the need to have large numbers of guards monitoring video feeds and patrons. The business benefits of digitally transformed guards are compelling. A National Hockey League security director says he used to have 300 guards manning 100 walk-through metal detectors. By moving to AI solutions, he can significantly reduce the number of scanning portals and guards, and most importantly redeploy and gain further operational efficiencies with his overall operational strategy. Changing staffing strategy This changes the staffing strategy significantly and elevates the roles of guards. Suddenly, a US$ 20-per-hour ‘job’ becomes a US$ 40-per-hour profession, with guards transformed into digital knowledge workers delivering better outcomes with digitally enabled staffs. Beyond that, these digitally transformed guards can spend a much higher percentage of their time focused on tasks that impact the fan experience – whether it’s keeping weapons out of the building, pro-actively dealing with unruly fans before a broader disruption occurs, or managing business operations that positively impact fan patron experience. Digitally transforming security guards Perhaps most important, digitally transforming security guards elevates the profession to a more strategic level, which means better pay for the guards, better service for clients of guard services, and an overall better experience for fans. That’s a perfect storm of goodness for everyone.

Why Visualization Platforms Are Vital For An Effective Security Operation Center (SOC)
Why Visualization Platforms Are Vital For An Effective Security Operation Center (SOC)

Display solutions play a key role in SOCs in providing the screens needed for individuals and teams to visualize and share the multiple data sources needed in an SOC today. Security Operation Center (SOC) Every SOC has multiple sources and inputs, both physical and virtual, all of which provide numerous data points to operators, in order to provide the highest levels of physical and cyber security, including surveillance camera feeds, access control and alarm systems for physical security, as well as dashboards and web apps for cyber security applications. Today’s advancements in technology and computing power not only have increasingly made security systems much more scalable, by adding hundreds, if not thousands, of more data points to an SOC, but the rate at which the data comes in has significantly increased as well. Accurate monitoring and surveillance This has made monitoring and surveillance much more accurate and effective, but also more challenging for operators, as they can’t realistically monitor the hundreds, even thousands of cameras, dashboards, calls, etc. in a reactive manner. Lacking situational awareness is often one of the primary factors in poor decision making In order for operators in SOC’s to be able to mitigate incidents in a less reactive way and take meaningful action, streamlined actionable data is needed. This is what will ensure operators in SOC truly have situational awareness. Situational awareness is a key foundation of effective decision making. In its simplest form, ‘It is knowing what is going on’. Lacking situational awareness is often one of the primary factors in poor decision making and in accidents attributed to human error. Achieving ‘true’ situational awareness Situational awareness isn’t just what has already happened, but what is likely to happen next and to achieve ‘true’ situational awareness, a combination of actionable data and the ability to deliver that information or data to the right people, at the right time. This is where visualization platforms (known as visual networking platforms) that provide both the situational real estate, as well as support for computer vision and AI, can help SOCs achieve true situational awareness Role of computer vision and AI technologies Proactive situational awareness is when the data coming into the SOC is analyzed in real time and then, brought forward to operators who are decision makers and key stakeholders in near real time for actionable visualization. Computer vision is a field of Artificial Intelligence that trains computers to interpret and understand digital images and videos. It is a way to automate tasks that the human visual system can also carry out, the automatic extraction, analysis and understanding of useful information from a single image or a sequence of images. There are numerous potential value adds that computer vision can provide to operation centers of different kinds. Here are some examples: Face Recognition: Face detection algorithms can be applied to filter and identify an individual. Biometric Systems: AI can be applied to biometric descriptions such as fingerprint, iris, and face matching. Surveillance: Computer vision supports IoT cameras used to monitor activities and movements of just about any kind that might be related to security and safety, whether that's on the job safety or physical security. Smart Cities: AI and computer vision can be used to improve mobility through quantitative, objective and automated management of resource use (car parks, roads, public squares, etc.) based on the analysis of CCTV data. Event Recognition: Improve the visualization and the decision-making process of human operators or existing video surveillance solutions, by integrating real-time video data analysis algorithms to understand the content of the filmed scene and to extract the relevant information from it. Monitoring: Responding to specific tasks in terms of continuous monitoring and surveillance in many different application frameworks: improved management of logistics in storage warehouses, counting of people during event gatherings, monitoring of subway stations, coastal areas, etc. Computer Vision applications When considering a Computer Vision application, it’s important to ensure that the rest of the infrastructure in the Operation Center, for example the solution that drives the displays and video walls, will connect and work well with the computer vision application. The best way to do this of course is to use a software-driven approach to displaying information and data, rather than a traditional AV hardware approach, which may present incompatibilities. Software-defined and open technology solutions Software-defined and open technology solutions provide a wider support for any type of application the SOC may need Software-defined and open technology solutions provide a wider support for any type of application the SOC may need, including computer vision. In the modern world, with everything going digital, all security services and applications have become networked, and as such, they belong to IT. AV applications and services have increasingly become an integral part of an organization’s IT infrastructure. Software-defined approach to AV IT teams responsible for data protection are more in favor of a software-defined approach to AV that allow virtualised, open technologies as opposed to traditional hardware-based solutions. Software’s flexibility allows for more efficient refreshment cycles, expansions and upgrades. The rise of AV-over-IP technologies have enabled IT teams in SOC’s to effectively integrate AV solutions into their existing stack, greatly reducing overhead costs, when it comes to technology investments, staff training, maintenance, and even physical infrastructure. AV-over-IP software platforms Moreover, with AV-over-IP, software-defined AV platforms, IT teams can more easily integrate AI and Computer Vision applications within the SOC, and have better control of the data coming in, while achieving true situational awareness. Situational awareness is all about actionable data delivered to the right people, at the right time, in order to address security incidents and challenges. Situational awareness is all about actionable data delivered to the right people Often, the people who need to know about security risks or breaches are not physically present in the operation centers, so having the data and information locked up within the four walls of the SOC does not provide true situational awareness. hyper-scalable visual platforms Instead there is a need to be able to deliver the video stream, the dashboard of the data and information to any screen anywhere, at any time — including desktops, tablets phones — for the right people to see, whether that is an executive in a different office or working from home, or security guards walking the halls or streets. New technologies are continuing to extend the reach and the benefits of security operation centers. However, interoperability plays a key role in bringing together AI, machine learning and computer vision technologies, in order to ensure data is turned into actionable data, which is delivered to the right people to provide ‘true’ situational awareness. Software-defined, AV-over-IP platforms are the perfect medium to facilitate this for any organizations with physical and cyber security needs.

Gunshot Detectors Shorten Response Times And Make Cities Safer
Gunshot Detectors Shorten Response Times And Make Cities Safer

Gunshot detectors use digital microphones installed on (or in) buildings or along streets that listen for evidence of gunshots, provide near instantaneous notification, triangulate the location of shooters and direction of a shot, detect the type of gun and ultimately aid in catching fleeing suspects and solving crimes. Gunshot detection is just one technology playing a role in the larger trend by city agencies to improve core city services. Cities are turning to what are referred to as ‘smart city’ solutions – new, innovative technologies that improve and maintain a high quality of life and ‘liveability’ for citizens. Several cities in the United States have implemented gunshot detection systems. Identifying And Deterring Gun Violence ShotSpotter, a provider of gunshot detection solutions that help law enforcement officials and security personnel identify, locate and deter gun violence, announced that seven new cities have deployed ShotSpotter technology in their communities. Gunshot detection systems can shorten the response time in an active shooter situation The new cities include Cincinnati, OH; Jacksonville, FL; Louisville, KY; Newburgh, NY; Pittsfield, MA; Syracuse, NY and St. Louis County, MO – joining the more than 90 jurisdictions that rely on ShotSpotter to ensure a fast, accurate response to gunfire incidents. Three existing ShotSpotter cities, New York City, Chicago and Birmingham have also recently expanded their coverage areas. Gunshot detection systems can shorten the response time in an active shooter situation. Early detection should be a primary aim, second only to prevention. Security professionals must be part of both of these areas, working in partnership with relevant administrators, local government, law enforcement, first responders and the community to help prevent and better respond to gun violence. Gunshot Localization Solution In addition, active shooter events – large or small – are almost always sudden and unexpected, which places a burden on security personnel to manage these risks without creating a prison-like environment. A gunshot localization solution can turn a video camera system into a real-time safety system in the event of an active shooter A gunshot localization solution can turn a video camera system into a real-time safety system in the event of an active shooter. Called ShotPoint, the system is completely automated. Working with a video management system (VMS), it can enable a video image of an active shooter to be provided in seconds based on the location of a gunshot. ShotPoint is a network of sensors which can be mounted on walls, ceilings, streetlight poles or other indoor or outdoor locations. Using a ‘sensor mesh approach’, ShotPoint reliably detects and localizes the source of gunfire; ranging from small handguns to high caliber rifles. The system can cover large indoor or outdoor areas such as schools, office buildings, retail centers, campuses, and parks. Accurately Provides Gunshot Location Each sensor has an array of four acoustic channels (microphones) that can locate the source of a gunshot sound, the time of arrival and the time distance of arrival. ‘Hearing’ shots from several vantage points (using multiple sensors) enables the system to take into account the angle and time of the sound, which vary in different environments, thus accurately providing the location of the gunshot. A ‘fusion processor’ box (at the edge) listens to the various sensor nodes and computes the location of the gunshot, relative to a floorplan and/or based on global positioning system (GPS) location. In an outdoor location, additional information may also be inferred, such as the trajectory of the gunshot and/or the caliber of the firearm.